MSP360 Installer Weaponized in Sophisticated Phishing Campaign Targeting Remote Access

Threat actors are distributing a legitimate MSP360 Remote Monitoring and Management installer disguised as meeting invitations, PDF documents, and software updates to trick users into executing malware. Once users run the deceivingly-named installer, attackers gain remote management capabilities on affected systems. Microsoft has issued warnings about this phishing campaign that combines social engineering with legitimate administrative tools.
Attackers are leveraging a widely-used remote management tool as the vehicle for a coordinated phishing operation. By disguising the installer within familiar communication formats—meeting notifications, document files, and software patches—threat actors exploit user trust in routine workplace interactions. The installer itself is genuine software; the deception lies entirely in the delivery method and social context designed to bypass user skepticism.
Once executed on a victim's machine, the compromised installer grants adversaries the same administrative access that legitimate IT teams use for system management and support. This dual-use nature of remote management tools makes them particularly attractive to attackers, as they operate within normal administrative channels once installed.
Organizations relying on remote management infrastructure could face significant operational disruption if employees inadvertently grant attackers system-level access. Small and mid-sized businesses using MSP360 may be particularly vulnerable if their security awareness training lags behind emerging social engineering tactics. The campaign demonstrates how attackers can weaponize legitimate enterprise tools, potentially affecting supply chains and client networks downstream from initially compromised systems.